Skip to content

Last updated · May 11, 2026

Privacy Policy

This Privacy Policy describes how LeagueHaus ("LeagueHaus", "we", "us", or "our") collects, uses, and shares information when you use our website and services (the "Service"). By using the Service, you agree to the practices described here. If you do not agree, do not use the Service.

1. Information We Collect

a. Information you provide

  • Account information — name, email address, and (optionally) a profile photo
  • League, venue, team, season, schedule, roster, and game-result data you submit
  • Announcements, comments, and other content you post inside a league
  • Support correspondence you send us

b. Information collected automatically

  • Log data (timestamps, request paths, status codes) needed to operate the Service
  • Approximate device and browser information derived from your user-agent
  • IP address, used for rate-limiting, abuse prevention, and approximate geolocation
  • Authentication cookies and session tokens (see Section 6)
  • If you opt in, a web-push subscription endpoint tied to your browser

2. How We Use Your Information

We use the information described above to:

  • Create and authenticate your account and keep you signed in
  • Operate league features — standings, schedules, rosters, notifications
  • Send transactional email (magic links, reminders, role changes)
  • Deliver web-push notifications you have opted into
  • Diagnose problems, prevent abuse, and secure the Service
  • Comply with legal obligations

Legal bases (EEA/UK users): We rely on (i) performance of a contract for delivering the core Service, (ii) our legitimate interests in operating, securing, and improving the Service, (iii) your consent where required (e.g., web-push notifications), and (iv) compliance with legal obligations.

3. How We Share Information

We do not sell your personal information. We share information only as follows:

  • With other members of your venue or league. Your name, profile photo, role, team membership, and game results are visible to other members of leagues you join. Venue and league administrators can see the email addresses of members in their venue or league.
  • With service providers (sub-processors) who process data on our behalf under contractual confidentiality and security obligations. See Section 4.
  • For legal reasons — to comply with applicable law, valid legal process, or to protect the rights, property, or safety of LeagueHaus, our users, or others.
  • In a business transfer — if LeagueHaus is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

4. Sub-processors

We use the following third-party providers to operate the Service. Each acts as a processor under our instructions:

  • Amazon Web Services (Amazon SES) — transactional email delivery (magic links, reminders, notifications)
  • Web Push providers (Apple Push Notification service, Mozilla autopush, Google FCM, and similar) — delivery of browser push notifications you have opted into
  • Hosting and infrastructure providers — application hosting, database storage, and content delivery

5. International Data Transfers

We and our sub-processors may store and process information in countries other than your own, including the United States. Where required by law, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses to transfer personal information across borders.

6. Cookies and Similar Technologies

We use only the cookies strictly necessary to operate the Service — primarily authentication and CSRF tokens. We do not use third-party advertising or cross-site tracking cookies. See our Cookie Policy for the full list and how to control them.

7. Data Security

We use industry-standard security measures, including encryption in transit (TLS), encryption of sensitive credentials at rest, role-based access controls, and least-privilege practices for internal access. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Data Retention

We retain your account and league data for as long as your account is active and as needed to provide the Service. If you delete your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain it for legal, accounting, or security reasons (for example, to enforce our Terms or comply with tax obligations).

9. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your information
  • Export a copy of your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where we rely on consent

To exercise these rights, contact us at privacy@leaguehaus.com. We will respond within the time required by applicable law.

10. EEA / UK Residents (GDPR)

If you are located in the European Economic Area or the United Kingdom, the rights described in Section 9 apply to you under the GDPR and UK GDPR. You also have the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority) if you believe our processing violates the law.

11. California Residents (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, the purposes for which it is used, request deletion or correction, and not be discriminated against for exercising your rights. We do not sell personal information and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA. To exercise these rights, contact us at privacy@leaguehaus.com.

12. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information to us, contact us and we will delete it. Some regions require a higher age threshold (e.g., 16 in parts of the EEA); we comply with the threshold applicable to your jurisdiction.

13. Do Not Track

We do not respond to Do Not Track (DNT) signals because there is no industry-standard interpretation of them. We do not engage in cross-site tracking regardless of DNT settings.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated version here with a new "Last updated" date. If changes are material, we will provide additional notice (for example, by email or an in-product banner) before the changes take effect.

15. Contact Us

For privacy-related questions or to exercise your rights, contact:

LeagueHaus
privacy@leaguehaus.com

🏆

YOU'RE UP!

Head to Area 1